I was hoping to get some clarification on this as there is no specific information that I could find in the documentation.
We obviously have these main ports in use for most Splunk installations.
Port 8000 - Splunk Web interface
Port 8089 - Splunk internal comms
Port 9997 - Splunk receiving
Would this graphic I put together accurately describe which .conf configurations affect each of the above?
I know there used to be some overlap with the some of the SSL configurations in server.conf which impact port 8000 but in recent Splunk releases it appears to have been separated out and compartmentalised to be contained in web.conf
Is there something missing from my diagram?
Are there any server.conf settings still affect the Splunk web on 8000 at all?